he Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the `pp_get_ip_address()` function when the "Use transients" feature is enabled. This makes it possible for attackers to bypass authorization by spoofing these headers with the IP address of a legitimately authenticated user, granted the "Use transients" option is enabled (non-default configuration) and the site is not behind a CDN or reverse proxy that overwrites these headers.
No configuration.
25 Oct 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-10-25 06:15
Updated : 2025-10-27 13:20
NVD link : CVE-2025-11244
Mitre link : CVE-2025-11244
CVE.ORG link : CVE-2025-11244
JSON object : View
No product.
Improper Authorization